Discover
Cyber Security District
Cyber Security District
Author: Cyber Security District
Subscribed: 41Played: 98Subscribe
Share
© Copyright 2024. All rights reserved.
Description
The interview podcast for cyber security professionals and for those who aspire to become one. We interview industry experts to get to know the latest trends, real life war stories and everything you need to know about this exciting industry.
52 Episodes
Reverse
The Rise of Identity-Based Attacks with Olivier Eyries | Saporo
What if you could see your entire attack surface the way a hacker does and fix it before they strike?
In this episode, hosts Laurens Jagt sit down with Olivier Eyries, co-founder and CEO of Saporo, one of Switzerland's fastest-growing cybersecurity startups. Saporo helps organisations stop hackers by identifying and eliminating identity risks before attackers can exploit them.
Olivier is a serial entrepreneur with two previous ventures under his belt, including one sold to Proofpoint in 2021. He and his co-founders built what he calls a "Google Maps for cybersecurity": a graph-based platform that maps every attack path, every permission, and every identity risk across an organisation's environment. In this conversation, he breaks down why identity-based attacks have exploded, what AI agents mean for the attack surface, and why fixing one permission can block millions of potential attack paths.
In this episode:
Olivier's journey: from dropping out at 21 to two exits and founding Saporo
Why identity-based attacks have exploded and AI is accelerating the trend
The graph-based approach: visualising attack paths the way hackers do
Non-human identities: why AI agents are the next major attack surface
How cutting one permission can block millions of attack paths
Saporo's 98% renewal rate and €7M funding round
The European funding gap and why Olivier is expanding into the US
Timestamps:
00:00 Introduction
01:03 Olivier's entrepreneurial journey: from dropout to two exits
04:12 The founding of Saporo: right tech, right team, right time
05:33 The Google Maps for cybersecurity concept
09:09 €7M raised and building through three stages of startup growth
11:02 Graph-based approach to identity risk and attack paths
16:14 How Saporo prioritises which attack paths to cut first
22:32 AI's impact on cybersecurity and Saporo's product roadmap
23:43 Non-human identities: the next major attack surface
29:19 What CISOs need to do right now about AI agents
34:17 Saporo's next milestones: US expansion and customer success
37:26 The European funding gap and why it matters for founders
43:49 Signal message to CISOs: give European founders a shot
44:42 Final thoughts: stay humble, ask the question, build now
Connect with the guests:
Olivier Eyries: https://www.linkedin.com/in/olivier-eyries/
Website: https://www.saporo.io/
Follow Cyber Security District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Jeroen Prinse on LinkedIn: https://www.linkedin.com/in/jprinse/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
What if your infrastructure was built secure from minute one and stayed that way?
In this special one year anniversary episode of Cyber Security District, host Jeroen Prinse sits back down with Mahdi Abdulrazak (CEO) and Kim van Lavieren (CTO) of Dawnguard, a security automation platform that turns approved security architecture directly into deployable cloud infrastructure as code.
One year in, having just closed a pre-seed round and raised €6.3 million in total funding and opening a new office in New York, Dawnguard is making a bold bet: that the only real answer to modern cyber threats isn't better detection or faster patching, it's building systems that are resilient by design from the very start.
Mahdi and Kim have both led security teams inside large organisations and lived through the same recurring nightmare: architecture locked in too early, security reviews arriving too late and a list of 50 findings that nobody has time to fix before the product ships. Dawnguard was built to break that cycle, with a collaborative canvas that lets teams design, validate and deploy secure infrastructure in minutes, with continuous drift detection to make sure it stays that way.
One year on, we look back at how far that idea has come and what's next as the company expands.
Key Takeaways:
You cannot patch your way out of agentic AI attacks, the only answer is building more resilient systems from the start
The hardest translation in security is from policy to architecture, ambiguity and contradictions there cascade into every layer below
Context is the missing ingredient in most security tooling: secure or insecure is a binary lens that doesn’t reflect reality
Drift detection only works when you know what was approved in the first place, that’s the advantage of integrating into the design lifecycle
Security decisions still belong to the business and engineers, Dawnguard removes the friction, not the ownership
The shift from protection to resilience is already happening: it’s not if you get breached, it’s how contained the blast radius is
European founders can compete, but capital conviction from investors matters as much as capital volume
Timestamps:
00:00 – Introduction
00:15 – Meet Dawnguard
00:48 – One year in: what proved Dawnguard was solving a real problem
01:30 – How customers are using the platform today: discover, design, deploy, monitor
03:20 – The shift-left moment: when architecture gets locked in and it’s already too late
05:15 – why organisations overestimate their resiliency requirements
06:15 – What Snyk, OPA and Sentinel leave unresolved
08:30 – Guardrails vs. findings: preventing vulnerabilities instead of just reporting them
09:30 – Policy to architecture to code to production: where is the hardest translation?
11:00 – The Mythos era: agentic AI and why patching is a losing strategy
12:50 – The shift from protection to resilience
15:00 – Blast radius reduction and the holistic trade-off view Dawnguard provides
16:45 – Drift detection: how Dawnguard tells a legitimate change from a malicious one
18:20 – Prompting redesigns for cost, sustainability, and resilience
20:00 – Bringing guardrails into the developer IDE in real time
22:25 – Who owns the security decision?
25:45 – European digital sovereignty: what it concretely means for Dawnguard
27:55 – Raising €6.3 million from European funds in year one
29:10 – What excites Mahdi and Kim most about the road ahead
30:40 – Final message: what CISOs should be doing differently a year from now
Connect with the guests:
Mahdi Abdulrazak: https://www.linkedin.com/in/mahdiabdulrazak/
Kim van Lavieren: https://www.linkedin.com/in/kim-v-0645931b4/
Website: https://www.dawnguard.io/
Follow Cyber Security District:
Jeroen Prinse on LinkedIn: https://www.linkedin.com/in/jprinse/
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
What does it take to build a cybersecurity company not once, but twice from the ground up?
In this episode of Cyber Security District, we sit down with Francisco Nina Rente, one of Portugal's most accomplished cybersecurity entrepreneurs. Francisco started his journey as a teenager tinkering with computers and quickly found his way into ethical hacking and open-source security communities. That curiosity became a career, which then led to a company.
His first venture grew from a university incubator into a 250-person operation delivering services across 22 countries, before being acquired by a global security group. After years scaling that business from the inside and taking on roles as country manager, CTO and board member, Francisco stepped away to build again.
This time, the mission is clearer: help organisations stop just detecting threats and start truly recovering from them. Art Resilia was born out of a conviction that the market was shifting from cybersecurity to cyber resilience, and Francisco positioned the company right at the centre of that shift.
Key Takeaways:
Cyber resilience is about recovery, not just defence
Focus beats opportunity-chasing, especially in the early days of a startup
The Commonwealth of a team always comes before individual interest
Trust-based security communication outlasts fear-based selling every time
Knowledge remains the core differentiator, even in the age of AI
Timestamps:
00:00 – Introduction
01:20 – From a family computer to a hacker mindset
04:00 – First paid gig: penetration testing for hardware
05:30 – Building Portugal's first incident response team at university
09:00 – Selling trust, not fear: early media and awareness work
11:00 – Scaling to 22 countries and finding the right investors
15:30 – The acquisition: joining a global security group
20:00 – Growing into CTO and leaving on his own terms
22:00 – The idea behind Art Resilia and reading the market shift
24:30 – The name: "The Art of Resilience"
25:00 – Where Art Resilia stands today: 50 people, 4 countries
27:00 – Why the Netherlands and Benelux?
28:00 – Lessons from 20 years of building: focus, people, pragmatism
33:00 – Culture, remote work, and hiring for values first
40:00 – What's next for Art Resilia in 3–5 years
43:00 – AI in cybersecurity: tool or transformation?
45:30 – Advice for young professionals entering the field
52:00 – Final message to CISOs: protect both business confidentiality and individual privacy
Connect with the guest:
Francisco Nina Rente: https://www.linkedin.com/in/frente/
Website: https://www.artresilia.com
Follow Cyber Security District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
What if you could clone your best cybersecurity consultant and put them to work on five engagements at once?
In this episode of Cyber Security District, we sit down with Leslie Clement and Erie Berhitu, co-founders of Clember AI, an EU-first, AI-native platform built to automate the repetitive, time-consuming work that holds cybersecurity consultants back. Both Leslie and Erie spent years grinding through the same manual loops at major consultancy firms document analysis, gap assessments, risk reports, roadmaps before deciding enough was enough.
Rather than build another consulting firm or hire more headcount, they built a platform. Clember AI now enables security consultants to run five or more client engagements simultaneously, with consistent, high-quality output every time. And they did it entirely bootstrapped, no VC, no investor pressure, just product-market fit and a clear-eyed vision of where cybersecurity consulting is heading.
In this episode, we explore:
How a company getting hacked on day one of the job launched Leslie’s career in cybersecurity
The year-long frustration that led Erie and Leslie to build Clember AI instead of another consulting firm
Why they chose to stay bootstrapped despite investor interest and why they don’t regret it
How Clember AI automates the full consulting lifecycle: document ingestion, gap analysis, risk translation, and reporting
Why consistency across junior and senior consultants is a bigger deal than most firms admit
The shift from hourly billing to monthly retainers and how Clember keeps consulting firms “interesting” to clients year three and beyond
Their vision: becoming the Datasnipper of cybersecurity consulting
Why embracing AI is non-negotiable for CISOs and why helping early-stage startups matters for the whole industry
Timestamps:
00:00 – Introduction
00:15 – Meet Leslie Clement and Erie Berhitu
01:40 – How Erie got into cybersecurity (and why it wasn’t exactly planned)
02:45 – Leslie’s rough first day: getting hacked with no tech team
04:00 – The shared frustration that sparked Clember AI
06:10 – Why they chose to build a tech firm instead of a consulting firm
08:30 – The first product concept: automating the questionnaire
11:20 – Who Clember AI is actually for: cybersecurity consultancy firms
14:00 – Billable hours vs. scale: how Clember changes the math
17:30 – The shift from hourly billing to monthly retainers and staying interesting in year three
22:00 – Will AI kill traditional consultancy? Leslie and Erie’s take
25:10 – How Clember works: document ingestion, gap analysis, risk translation, roadmaps
29:00 – Consistency across consultant seniority levels
31:30 – Hiring technical talent as non-technical founders
34:00 – Staying bootstrapped despite VC interest and why pivoting was easier without investor pressure
38:30 – What made Clember appealing at an early stage
41:00 – The hiccups: work-life balance, family, and knowing when to step away
44:30 – Gut feeling vs. rational decision-making as founders
48:00 – The vision: Clember as the Datasnipper for cybersecurity consulting
51:30 – What’s next: new markets, sales hires, and scaling customer success
54:00 – Data privacy and security by design inside Clember
57:00 – Final message to CISOs: embrace innovation, and back the startups
Connect with the guests:
Leslie Clement: https://www.linkedin.com/in/leslie-clement/
Erie Berhitu: https://www.linkedin.com/in/eberhitu/
Website: https://www.clember.ai/
Follow Cyber Security District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict
In this episode of Cyber Security District, we speak with Tom Leijte, founder of Passguard, one of the most exciting emerging cybersecurity companies in the Netherlands. Passguard helps organizations detect when infected devices, stolen credentials, and active sessions show up on criminal marketplaces, giving security teams early visibility before exposure turns into a breach.
Tom shares how his journey started outside of “traditional” cybersecurity, working in private investigations where dark web intelligence was already part of high-stakes screening work. Together with his technical co-founder, he built the capabilities to infiltrate closed criminal forums and surface the kind of forensic-level logs most companies never see until it’s too late.
In this episode, we cover:
Using dark web intelligence for sensitive employee screening
Why “classic” dark web monitoring often gets deprioritized by security teams
The infostealer shift: stolen session tokens, not just leaked passwords
How session theft can bypass MFA and why that changes the game
How criminal marketplaces work (and how trust is built among criminals)
How Passguard infiltrates closed forums using reputation, escrow, and long-term access
Building a European-first solution and partnering with MSSPs / security platforms
Scaling after investment: team growth, ICP clarity, and market expansion
Timestamps:
00:00 – Intro
00:15 – Meet Tom Leijte and Passguard’s mission
00:37 – Early visibility: exposure before it becomes a breach
01:22 – Tom’s background in private investigations
02:13 – Screening sensitive roles using open-source + dark web sources
03:47 – Why dark web intelligence matters for organizations
04:39 – How Passguard started (and the co-founder story)
05:53 – What surprised Tom most about the dark web
06:20 – Data breaches vs data brokers: what ends up for sale
07:20 – Discovering infostealers and why they’re different
08:17 – Session tokens, MFA bypass, and the “unmanaged endpoint” problem
10:01 – What infostealers capture (sessions, access, and more)
11:10 – Why SaaS + remote work + BYOD changed attacker economics
12:27 – Supplier and branch-office risk: the blind spot organizations miss
14:31 – Why classic “dark web monitoring” wasn’t landing in the market
15:38 – The Mom Test and learning to run real customer conversations
18:08 – Reframing the problem: focusing on infostealer exposure
20:38 – How the dark web works (no “bookmark”, reputation, escrow)
23:11 – Passguard’s approach: bots, reputation, and long-term infiltration
25:55 – Real-world example: infostealers and large-scale government breaches
27:37 – What stolen access is worth and how it gets packaged for sale
29:19 – Screenshots, persistence, and “always up-to-date” stolen sessions
30:05 – Educating customers and turning awareness into action
31:03 – What Passguard delivers: evidence, context, and early alerts
33:08 – The Snowflake case: old credentials, massive impact
36:06 – Scaling after investment: pressure, growth, and coping
37:18 – Why Tom chose experienced cyber investors and operators
39:43 – Passguard as intelligence inside MSP/MSSP security workflows
41:45 – Team expansion and what roles matter most next
43:27 – ICP clarity and European market expansion
45:27 – Signal message to CISOs: give startups a chance early
46:50 – Outro
Connect with the guests:
Tom Leijte: https://www.linkedin.com/in/tom-leijte-01596536/
Website: https://www.passguard.com/
Follow Cybersecurity District:
Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/
Website: https://www.cybersecuritydistrict.com/
All channels & newsletter: https://beacons.ai/cybersecuritydistrict



